Skip to content

Register rust-libp2p with Github's Dependabot #1743

@mxinden

Description

@mxinden

As the title says, I would like to suggest registering rust-libp2p with Github's Dependabot.

Dependabot creates pull requests to keep your dependencies secure and up-to-date.

You can find more details here: https://dependabot.com/

I think Dependabot would remove a lot of toil around dependency management for us maintainers. At the same time it would ensure that rust-libp2p uses most recent versions of its dependencies and thus enforcing rust-libp2p staying in sync with recent security releases. I am personally using it on most of my personal projects, thus far without issues.

What do people think? Any objections?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions